This forum has been moved here:
Helicon Tech Community Forum

  Active TopicsActive Topics  Display List of Forum MembersMemberlist  HelpHelp   RegisterRegister  LoginLogin
HotlinkBlocker
 Helicon Tech : HotlinkBlocker
Subject Topic: IIS 6 Q (Topic Closed Topic Closed) Post ReplyPost New Topic
Author
Message << Prev Topic | Next Topic >>
intenzity
Newbie
Newbie


Joined: 06 July 2007
Location: United States
Online Status: Offline
Posts: 1
Posted: 06 July 2007 at 3:07pm | IP Logged  

Installed HotLinkBlocker, works great... now real quick question, perhaps I am missing something here, but in the hotblocker config, I have set up LINK security on a published content directory on our IIS server which stores tons of wav's, gif's, etc. Config below:

#################################################
# HotlinkBlocker Configuration file

# Version 1, 4, 0, 56


Signature=
LinkExpires=3600
NotifyOrder=MEDIUM


[Protect]
LINK  /members/sound%20effects http://www.domainname.com


[ReferersBlackList]
[ReferersWhiteList]
[UserAgentsBlackList]
[UserAgentsWhiteList]

 

This config prevents anyone from linking to any files contained in that folder, and if tried it redirects them to the main site index.  Works great, now...

All I did was add a second trailing "/" and the file is obtainable.

For example:  http://www.mydomain.com/members/sounds/test.wav will redirect to the site index when HB is turned on.

http://www.mydomain.com//members/sounds/test.wav is obtainable simply by adding the second trailing slash (which I found is able to be used infinatly, for example, http://www,mydomain.com/////////////members/sounds/test.wav will also allow the user to download the same exact file.

I guess my first question is, WHY is that possible?   

 

Back to Top View intenzity's Profile Search for other posts by intenzity Visit intenzity's Homepage
 
Yaroslav
Admin Group
Admin Group


Joined: 15 August 2002
Online Status: Offline
Posts: 6521
Posted: 16 July 2007 at 8:06am | IP Logged  

Please download build 57, it should fix this problem.

__________________
Yaroslav Govorunov,
Helicon Tech
Back to Top View Yaroslav's Profile Search for other posts by Yaroslav Visit Yaroslav's Homepage
 

Sorry, you can NOT post a reply.
This topic is closed.

  Post ReplyPost New Topic
Printable version Printable version

Forum Jump
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot delete your posts in this forum
You cannot edit your posts in this forum
You cannot create polls in this forum
You cannot vote in polls in this forum